MALICIOUS — rusawupevu.pdf
MALICIOUS — rusawupevu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ac364df6ae19b0b10bb49ca9c541d12c8bc01e5bb499eeee246cac6ab757d22b - SHA-1:
73f8487f58eccd4c03d05ecd949b10bcbe0f58a6 - MD5:
fd33d6c023cfe100c6237a86a5c631c1 - ssdeep:
3072:fZC2FE1qyYZsKbJ+xbURWKDvsjlYPFmoZlRb/rIMFSWV7jDD5y:xC2PyrMcbg5kSFmobRbTbNxE - TLSH:
T16A3DE1F3718BDE4D3E8B8B936567261C6091C7C860336B90108DB27CC4A86EEBF51991 - Submitted as: rusawupevu.pdf
- File type: pdf · Size: 124100 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://e7c02ae7-ba66-49ef-8fe7-d4c265c54a1b.filesusr.com/ugd/bc5701_cbb7a47957a3477bbe87f6fdc24a01ec.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://e7c02ae7-ba66-49ef-8fe7-d4c265c54a1b.filesusr.com/ugd/bc5701_cbb7a47957a3477bbe87f6fdc24a01ec.pdf?index=true, https://e809654a-a95b-4dbc-a338-24085255a2f8.filesusr.com/ugd/1b6cec_512b43e01a984d3c84e0b85b4ff5ad18.pdf?index=true, https://fed4949e-3809-4fc0-a28b-84c5d390f589.filesusr.com/ugd/94482e_89f8d23ef56b4295963dc4d3b306107b.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/dRGGkpkNhSI/wb?keyword=aprendizajes%20clave%20educacion%20fisica%20segundo%20de%20primaria
- https://e7c02ae7-ba66-49ef-8fe7-d4c265c54a1b.filesusr.com/ugd/bc5701_cbb7a47957a3477bbe87f6fdc24a01ec.pdf?index=true
- https://e809654a-a95b-4dbc-a338-24085255a2f8.filesusr.com/ugd/1b6cec_512b43e01a984d3c84e0b85b4ff5ad18.pdf?index=true
- https://fed4949e-3809-4fc0-a28b-84c5d390f589.filesusr.com/ugd/94482e_89f8d23ef56b4295963dc4d3b306107b.pdf?index=true
- https://91953a53-6f32-4f2a-9b2e-0f954541ff31.filesusr.com/ugd/dad90e_0d40e8a9d0fe44b99c9304057b403685.pdf?index=true
- http://jekewalesobe.rf.gd/38997659120.pdf
- https://7915398d-c9c2-4241-abdb-40cf742e4b8d.filesusr.com/ugd/d4df0f_9d5f8a7d815145a5b3360c460d13b58a.pdf?index=true
- https://dusivasawomila.weebly.com/uploads/1/3/4/6/134660852/xutoxigazeparu.pdf
- https://e6e31949-ba74-43ae-8e0c-2243355e89fd.filesusr.com/ugd/69e259_1412fd69351a4c1ca1aaa88c485e8f0b.pdf?index=true
- https://3b0fe5ff-7f86-489c-8138-fc984e51136c.filesusr.com/ugd/bfd78a_5524429bf1ad4d5b95752dee8fbb12e8.pdf?index=true
- http://vladmer.ru/is_season_3_of_attack_on_titan_the_last2fxdp.pdf
- https://979cd01f-16ea-4d2c-b189-234964c95597.filesusr.com/ugd/d4c4cf_8f4dd1f02c7846d994c3b757fe4f8289.pdf?index=true
- http://kavakedego.scienceontheweb.net/wemulozapejom.pdf
- http://wekanisa.scienceontheweb.net/vepawirufax.pdf
- http://zelawiture.epizy.com/82665142229.pdf
- http://modernstyle.pro/chavo_del_8_dibujonmh2g.pdf
- http://ceter.xyz/does_misa_die_death_noteq10s1.pdf
- https://76c9fb28-c10e-4950-85be-37de24a2ede8.filesusr.com/ugd/fa32a6_8f8b75a5061b4d0782088757e6594e44.pdf?index=true
- https://goxatuzibifonev.weebly.com/uploads/1/3/0/7/130739188/4250039.pdf
- http://blue-tick-central.com/singer_model_9410_sewing_machine_manual3id7f.pdf
- http://taroveruwidiba.onlinewebshop.net/refunawil.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- feedproxy.google.com
- e7c02ae7-ba66-49ef-8fe7-d4c265c54a1b.filesusr.com
- e809654a-a95b-4dbc-a338-24085255a2f8.filesusr.com
- fed4949e-3809-4fc0-a28b-84c5d390f589.filesusr.com
- 91953a53-6f32-4f2a-9b2e-0f954541ff31.filesusr.com
- 7915398d-c9c2-4241-abdb-40cf742e4b8d.filesusr.com
- dusivasawomila.weebly.com
- e6e31949-ba74-43ae-8e0c-2243355e89fd.filesusr.com
- 3b0fe5ff-7f86-489c-8138-fc984e51136c.filesusr.com
- vladmer.ru
- 979cd01f-16ea-4d2c-b189-234964c95597.filesusr.com
- kavakedego.scienceontheweb.net
- wekanisa.scienceontheweb.net
- zelawiture.epizy.com
- modernstyle.pro
- ceter.xyz
- 76c9fb28-c10e-4950-85be-37de24a2ede8.filesusr.com
- goxatuzibifonev.weebly.com
- blue-tick-central.com
- taroveruwidiba.onlinewebshop.net
- www.w3.org
- purl.org
- ns.adobe.com
- jekewalesobe.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report